Atlas / MCP servers / xwang152-jack / WeChat Official Account

WeChat Official AccountSAFE

mcp/xwang152-jack/wechat-official-account

微信公众号MCP服务器 - WeChat Official Account MCP Server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
21 17r · 4w · 0d
Transport
sse · stdio
License
MIT
Stars
64
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

一个为 AI 应用提供微信公众号 API 集成的 MCP (Model Context Protocol) 服务项目。

作者: xwang152-jack 更新日期: 2026年05月24日

🚀 项目概述

本项目基于 MCP 协议,为 AI 应用(如 Claude Desktop、Cursor、Trae AI 等)提供完整的微信公众号 API 集成。通过标准化的工具接口,AI 应用可以轻松管理微信公众号的用户、标签、菜单、素材、草稿、发布、消息、数据统计、二维码、评论、黑名单等所有核心功能。

当前版本: v2.2.0 (查看 CHANGELOG | v1.1.0 Release Notes)

v2.2.0 更新: 新增 6 个工具模块(二维码、短链接、评论管理、黑名单、客服账号、账号管理),从 15 个工具扩展到 21 个工具。

📖 文档导航

  • 功能总览 (FEATURES_OVERVIEW.md) - v2.0.0 完整功能介绍、对比表格和使用场景
  • 更新日志 (CHANGELOG.md) - 版本历史和详细更新内容
  • 开发者指南 (CLAUDE.md) - 架构说明、开发规范、常见模式

外部资源

✨ 核心功能

  • 🔐 认证管理: 安全管理微信公众号 AppID、AppSecret 和 Access Token
  • 📁 素材管理: 上传、获取、管理临时和永久素材
  • 📝 草稿管理: 创建、编辑、管理图文草稿
  • 📢 发布管理: 发布草稿到微信公众号
  • 💾 本地存储: 使用 SQLite 本地存储配置和数据
  • 🔧 MCP 集成: 完全兼容 MCP 协议标准
  • 🛡️ 安全增强(v1.1.0): 支持敏感字段加密存储与日志脱敏,跨域来源白名单配置

🛠️ 技术栈

  • 运行时: Node.js 18+
  • 语言: TypeScript
  • 协议: MCP (Model Context Protocol)
  • 数据库: SQLite
  • HTTP 客户端: Axios
  • 参数验证: Zod
  • 构建工具: Vite

📦 快速开始

方式一:使用 npx(推荐)

直接使用 npx 运行,无需安装:

# 启动 MCP 服务器
npx wechat-official-account-mcp mcp -a  -s 

# 示例
npx wechat-official-account-mcp mcp -a wx1234567890abcdef -s your_app_secret_here
提示:如使用 SSE 模式,请设置 CORS_ORIGIN 为允许访问的域名白名单。

方式二:全局安装

# 全局安装
npm install -g wechat-official-account-mcp

# 启动服务
wechat-mcp mcp -a  -s 

方式三:本地开发

# 1. 克隆项目
git clone https://github.com/xwang152-jack/wechat-official-account-mcp.git
cd wechat-official-account-mcp

# 2. 安装依赖
npm install

# 3. 构建项目
npm run build

# 4. 启动服务
node dist/src/cli.js mcp -a  -s 

CLI 参数说明

  • -a, --app-id : 微信公众号 AppID(必需)
  • `-s, --app-s
Read from source at commit ef650a6aba94OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add wechat-official-account-mcp --env WECHAT_MCP_SECRET_KEY=${WECHAT_MCP_SECRET_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "wechat-official-account-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "WECHAT_MCP_SECRET_KEY": "${WECHAT_MCP_SECRET_KEY}"
      }
    }
  }
}
03

Exposed tools (21)

17 read · 4 write · 0 destructive.

ToolRiskDescription
wechat_accountread微信公众号账号管理工具。查询API调用次数配额、重置API调用次数。用于监控和管理公众号接口调用频率。
wechat_authread管理微信公众号认证配置和 Access Token
wechat_auto_replyread微信公众号自动回复规则 - 查询当前的自动回复规则配置
wechat_blacklistread微信公众号黑名单管理工具。查看黑名单列表、拉黑/取消拉黑用户。被拉黑的用户无法收到公众号消息。
wechat_commentread微信公众号评论管理工具。管理已群发文章的评论,包括打开/关闭评论、查看评论列表、精选/删除/回复评论。
wechat_customer_serviceread微信公众号客服消息 - 发送客服消息(文本、图片、语音、视频等),获取聊天记录
wechat_draftread管理微信公众号草稿
wechat_kf_accountread微信公众号客服账号管理工具。添加、修改、删除客服账号,获取客服列表。客服账号用于管理多客服人员。
wechat_mass_sendwrite微信公众号群发消息 - 根据标签或OpenID列表群发图文、文本、图片等消息,支持删除和预览
wechat_media_uploadwrite上传和管理微信公众号临时素材(图片、语音、视频、缩略图)
wechat_menuread微信公众号自定义菜单管理 - 创建、查询、删除菜单,支持个性化菜单
wechat_permanent_mediaread管理微信公众号永久素材,支持添加、更新、获取、删除、列表和统计操作
wechat_publishwrite管理微信公众号文章发布
wechat_qrcoderead微信公众号二维码管理工具。创建临时/永久二维码,获取二维码图片URL。适用于渠道追踪、线下推广等场景。
wechat_short_urlread微信公众号长链接转短链接工具。将长URL转换为短链接,适用于二维码、短信等场景。
wechat_statisticsread微信公众号数据统计分析 - 获取图文、消息、接口等数据分析
wechat_subscribe_msgread微信公众号订阅通知 - 发送一次性订阅通知给用户
wechat_tagread微信公众号标签管理 - 创建、编辑、删除标签,为用户批量打标签/取消标签
wechat_template_msgread微信公众号模板消息 - 发送模板消息、管理模板、设置行业、获取行业信息
wechat_upload_imgwrite上传图文消息内所需的图片,不占用素材库限制
wechat_userread微信公众号用户管理 - 获取用户列表、用户信息、设置备注名、查看用户增减数据等
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMInventory / provenance · inv.binary · CWE-1104
data/wechat-mcp.db
wechat-mcp.db
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/shared/init.ts:2
import { WechatMcpTool } from '../../mcp-tool/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/shared/init.ts:3
import { AuthManager } from '../../auth/auth-manager.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/shared/init.ts:6
import { logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/shared/init.ts:7
import { getVersion } from '../../utils/version.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/shared/types.ts:2
import { AuthManager } from '../../auth/auth-manager.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, commander, cors, crypto-js, dotenv, express, form-data
Why it matters. 47 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ef650a6aba94full audit observations/trust-audit/mcp-server/xwang152-jack__wechat-official-account.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ef650a6aba94SAFEB89first audit
06

Questions

What is the WeChat Official Account MCP server?

微信公众号MCP服务器 - WeChat Official Account MCP Server

What tools does WeChat Official Account expose?

21 in total: 17 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is WeChat Official Account safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does WeChat Official Account need?

It reads WECHAT_MCP_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does WeChat Official Account run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as wechat-official-account-mcp at 2.2.0.

How current is this page?

The grade is for one exact copy of the source (ef650a6aba94), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement